Skip to content
RiskTemplates · The Daily Brief Saturday, August 22, 2026
Wire SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed AUG 20

Topic Privacy & Incident Response

When privacy laws collide with a real incident.

State privacy laws, breach notification timelines, and incident response playbooks — for the team that has to decide what to disclose, to whom, and by when. Aligned with NIST SP 800-61, state breach laws, and federal incident reporting.

◆ CCPA · CPRA · state privacy laws · NIST SP 800-61 · federal breach rules

◆ What you'll find here

Privacy and incident response, treated as one program.

◆ 01

State privacy laws

CCPA, CPRA, Colorado, Connecticut, Texas, and every state law that follows the same pattern. The obligations, the timelines, and what your privacy program actually has to do.

◆ 02

Breach notification

All 50 state breach laws plus federal sector rules (HIPAA, GLBA, SEC cyber, banking incident reporting). Decision trees, notification templates, and the timelines that actually trigger reporting.

◆ 03

IR playbooks

Ransomware, BEC, third-party breach, insider, lost device — the eight playbook patterns that cover most real incidents. Built on NIST SP 800-61 and what actually happens in the room.

◆ Privacy & incident response templates

Tools for privacy + IR teams.

Decision trees, notification templates, IR runbooks, and the evidence you need to show regulators and bank partners.

Template
$69

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Template
$69

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

82+

Privacy & IR articles

50

State breach laws covered

US

CCPA · CPRA · NIST SP 800-61 · sector rules

◆ Latest analysis

From the journal.

Data Privacy

Global Privacy Control for Financial Services: A State-by-State Scope Test

A practical Global Privacy Control guide for financial services: state scope, GLBA exemptions, signal handling, testing, and evidence.

· 10 min read

Data Privacy

California Just Fined a Data Broker $116K for Making Opt-Out Too Hard. Your Fintech's Data Practices Are Next.

CalPrivacy ordered LocateSmarter to pay $116,490 over registration and opt-out violations, then fined Cybba $52,400 two days later.

· 9 min read

Data Privacy

Washington MHMDA for Fintech: The GLBA Data Exemption and CPA Enforcement

Washington's My Health My Data Act has a data-level GLBA exemption and uses the Consumer Protection Act for public and private enforcement.

· 8 min read

Data Privacy

Location Data Enforcement in 2026: Kochava, GM/OnStar, and Allstate/Arity

Separate the 2026 Kochava and GM orders, California's GM settlement, Texas's Allstate/Arity suit, and private location-data litigation.

· 7 min read

Data Privacy

NYDFS's First 2026 Cybersecurity Fine Wasn't About the MOVEit Hack. It Was About What Happened After.

On April 29, 2026, NYDFS issued a $2.25 million consent order against Delta Dental of New York—its first 2026 cybersecurity enforcement action. The underlying breach was a 2023 MOVEit zero-day. The violations were late notification, inadequate data disposal, and insufficient incident response plan detail. And the consent order bars insurance reimbursement. Here's what the enforcement record tells your program.

· 10 min read

Incident Response

CIRCIA Status in August 2026: No Final Rule and No Current 72-Hour Duty

CIRCIA remains in rulemaking. Separate its proposed 72- and 24-hour reports from the banking agencies' existing 36-hour notification rule.

· 5 min read

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.